Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Azure Logic Apps | 7/8/2026 | 7/8/2026 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.9) | 1.7% | — | Microsoft Azure Service BUS | 7/8/2026 | 7/8/2026 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.9) | 0.82% | — | Microsoft Azure Active Directory | 7/8/2026 | 7/8/2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Cosmos DB | 30/7/2026 | 4/8/2026 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Azure Portal | 24/7/2026 | 29/7/2026 | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.86% | — | Microsoft Azure APP Service FOR Linux | 24/7/2026 | 6/8/2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Kubernetes Service | 24/7/2026 | 29/7/2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.92% | — | Microsoft Azure KEY Vault | 24/7/2026 | 7/8/2026 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.92% | — | Microsoft Azure DNS | 24/7/2026 | 7/8/2026 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.55% | — | Microsoft Azure AI Search | 24/7/2026 | 29/7/2026 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.79% | — | Microsoft Azure RED HAT Openshift | 24/7/2026 | 7/8/2026 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.2) | 0.70% | — | Microsoft Azure API Management | 24/7/2026 | 17/8/2026 | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Crítica (9.8) | 0.43% | 💥 PoC | Microsoft Azure API ManagementAI | 21/7/2026 | 5/10/2026 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words,… | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Azure Cyclecloud | 14/7/2026 | 22/7/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Cyclecloud | 14/7/2026 | 22/7/2026 | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (8.2) | 0.52% | 💥 PoC | Microsoft Azure Spring Cloud | 14/7/2026 | 24/7/2026 | Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Alta (8.8) | 0.50% | — | Microsoft Azure Connected Machine Agent | 14/7/2026 | 18/8/2026 | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. | |
| Pendiente de análisis | Media (6.9) | 0.47% | 💥 PoC | Microsoft Azure Blob StorageAI | 3/7/2026 | 6/7/2026 | The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Openai | 2/7/2026 | 7/7/2026 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.70% | — | Microsoft Azure Synapse | 2/7/2026 | 7/7/2026 | Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.2) | 0.20% | — | OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and… | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Azure Synapse | 19/6/2026 | 29/6/2026 | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Active Directory | 19/6/2026 | 24/6/2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. |